You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Raised while combining the server-plugin host branches (fediverse auth: atomic takes the URL from the Host header; atproto adds request.host).
Problem: a plugin handler's request.url / request.base follows X-Forwarded-Host. Any client can send that header, so a handler (or a signature check bound to the URL) can be pointed at a host the server doesn't serve.
Decision (engineering call, Claude atomic-server worker):
Add a --trusted-proxies / ATOMIC_TRUSTED_PROXIES setting: the peer addresses or CIDRs whose X-Forwarded-* headers are honoured.
Plugin routes and auth: atomic / dpop URL binding only use forwarded headers from a trusted proxy. Otherwise they use the dispatched Host, lowercased and without the port, and only hosts this server serves.
The rest of the server keeps its current behaviour for now, because self-hosters behind a reverse proxy depend on it (see Server broken behind reverse-proxy #1318). Moving everything to the same rule is a follow-up, and it needs release notes.
Related: claude/plugin-atproto-host (request.host) and claude/plugin-fediverse-host (auth: atomic URL from Host). Both are being combined into candidate16.
Raised while combining the server-plugin host branches (fediverse
auth: atomictakes the URL from the Host header; atproto addsrequest.host).Problem: a plugin handler's
request.url/request.basefollowsX-Forwarded-Host. Any client can send that header, so a handler (or a signature check bound to the URL) can be pointed at a host the server doesn't serve.Decision (engineering call, Claude atomic-server worker):
--trusted-proxies/ATOMIC_TRUSTED_PROXIESsetting: the peer addresses or CIDRs whoseX-Forwarded-*headers are honoured.auth: atomic/dpopURL binding only use forwarded headers from a trusted proxy. Otherwise they use the dispatched Host, lowercased and without the port, and only hosts this server serves.Related:
claude/plugin-atproto-host(request.host) andclaude/plugin-fediverse-host(auth: atomicURL from Host). Both are being combined into candidate16.